Skip to content

[APP-ARCH-0] Define desktop application shell architecture - #127

Merged
DJAscendance merged 1 commit into
mainfrom
design/app-shell-architecture
Oct 8, 2026
Merged

DJAscendance merged 1 commit into
mainfrom
design/app-shell-architecture

Conversation

@DJAscendance

Copy link
Copy Markdown
Collaborator

Summary

Adds docs/architecture/DESKTOP_APPLICATION_SHELL_REVIEW.md, the APP-ARCH-0 desktop application shell architecture with the owner-approved direction (O1–O6).

This PR does not implement the shell migration.

This PR does not start SHELL-0, #121, #122, UI-C0, UI-1, or WD2-E.

Documentation only. No product code, dependency, CLAUDE.md/AGENTS.md/WD.md, issue or Project change.

Current shell findings

  • One window navigating between three separate HTML pages. Every profile switch is a full loadFile reload, which re-parses X_ITE (1.3 MB) and, on the editor page, the 1.4 MB editor bundle.
  • Main is the real state owner. The Mall page cannot rehydrate after a round-trip to the editor.
  • renderer/editor.js (1,448 lines) centrally registers every command and panel, and owns the session, analysis, picking, recovery and QA hooks.
  • No mount/dispose lifecycle: unsubscribe handles are discarded.
  • Module dependencies exist only as script-tag order across ~30 window.* globals.
  • Chrome, CSS and CSP are copied across pages, and the CSP copies have drifted.
  • main.js (1,573 lines) includes ~610 lines of QA capture server and all 43 IPC handlers inline.

Decisions (owner-approved)

  • O1 Electron: KEEP WITH MAJOR SHELL REFACTOR.
  • O2 Renderer: KEEP FRAMEWORK-FREE, with first-party contribution/disposable lifecycle contracts.
  • O3 Bundling: esbuild approved in principle for first-party renderer entrypoints. Current repository policy is unchanged until a later approved lane updates the rules.
  • O4 Persistent shell: one persistent application shell is the target, reached in stages; no big-bang rewrite.
  • O5 Security: future separate lane, provisionally SEC-SHELL-0 — Renderer-Supplied Path Authority Audit and Confinement (no issue created).
  • O6 [UI-0-I2] Workspace behavior and command UX #121: #121 SHOULD WAIT FOR SHELL FOUNDATION — shell foundation = SHELL-0 only.

Sequencing

APP-ARCH-0 → SHELL-0 → #121 / #122 → Shell-1a (structure) → Shell-1b (hardening, separately gated)
→ Shell-2 → Shell-3 → Shell-4 (persistent shell; close guard before default) → UI-1 / Shell-5

Findings promoted to required work

  • Path authority: mall:openPath, mall:check and shell:revealInFolder act on renderer-supplied paths. This conflicts with main-process path ownership and needs its own audit. Exploitability is not asserted, and the handlers are not changed here.
  • Dirty close: closing the window with unsaved edits does not prompt; only the recovery snapshot preserves them. A dirty-document close guard (Save / Discard / Cancel, with recovery reserved for abnormal termination) is required before the persistent shell becomes the default.

Related

#33 · #121 · #122 · #36 · #37 · #38 · #43 · #50

Validation

  • git diff --check clean.
  • Exactly one file changed.
  • All 30 required APP-ARCH-0 subject areas present.

APP-ARCH-0. Records the owner-approved desktop application shell
architecture for WRL Forge: keep Electron with a staged shell refactor,
stay framework-free, esbuild approved in principle for first-party
renderer entrypoints (not active until a later lane updates repository
rules), and one persistent application shell as the target.

Defines SHELL-0 (Shell Contracts and Measurement) as the next foundation
lane; #121 waits for SHELL-0 only. Records the renderer-supplied path
authority finding (future SEC-SHELL-0) and the dirty-document close
guard as required before the persistent shell becomes default.

Documentation only. No product code, dependency or repository-rule
change.

Signed-off-by: Ryan Bundy <ascendance@skate.fm>
@DJAscendance
DJAscendance merged commit 957102a into main Oct 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant